跳转到正文
报告库
用途分类 / 其他用途

Image Skill 安全审计

作者说它能做什么(原文)

When the user wants to create, generate, edit, or optimize images for marketing — blog heroes, social graphics, product mockups, profile banners, listing visuals, or brand assets. Also use when the user mentions 'AI image generation,' 'generate an image,' 'create a graphic,' 'product mockup,' 'hero image,' 'social media graphic,' 'banner image,' 'cover photo,' 'profile banner,' 'listing screenshot

第三方安全检查结论

发现安全风险

已检查文件
3
发现的风险
2
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

真实产品截图和品牌素材可能被上传给第三方图片服务

原文依据:2 处
发现了什么

工作流要求捕获真实产品截图,而提示指南建议把产品截图、品牌素材或风格参考上传给 Flux 等外部模型。真实截图可能含客户资料、内部功能、测试账户、访问令牌或未发布设计;品牌文件也可能是保密资产。

为什么需要注意

若未先脱敏,这些内容会离开本地环境并受第三方服务的保存、训练、日志和访问政策约束,可能造成商业资料或个人数据泄露。

存在有条件的数据披露风险:技能先建议捕获真实产品截图,参考指南又明确建议将产品截图、品牌素材或风格参考上传至 Flux。若用户采用该多图参考流程,素材会交给第三方服务处理;来源没有要求先检查或遮盖客户信息、令牌、内部功能或未发布设计。用户可要求作者加入上传前的敏感信息审查、脱敏步骤,并允许仅使用本地或获批服务。

SKILL.md:190来自说明文档打开原文件
1. **Capture real screenshots** of your product at 2x resolution2. **Frame in device mockups** — use browser frame, laptop, or phone templates3. **Add context** — callout arrows, feature labels, before/after comparisons4. **Annotate with code** — Hyperframes or HTML/CSS for programmatic overlays
查看另外 1 个位置
references/ai-image-prompting.md:142来自说明文档打开原文件
- **Multi-image reference** is the killer feature — upload product screenshots, brand assets, or style references- Best for **brand consistency** across a set of images- Use Flux Pro for final assets, Flux Dev for rapid iteration- Flux Klein for high-volume batch generation (cheapest)- Style transfer via reference images > style keywords in prompt- Prompts can be shorter than other models — the references do heavy lifting
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。发现 1 项风险
中风险

JPEG 优化示例会通配修改当前目录中的所有 JPG 并移除元数据

原文依据:1 处
发现了什么

`jpegoptim --max=80 --strip-all *.jpg` 会处理当前目录匹配的每个 JPG,重新压缩并删除全部元数据。该命令没有先备份、预览目标或限制到输出目录。

为什么需要注意

运行位置错误或目录中混有原始照片时,用户可能不可逆地损失画质以及 EXIF、版权、拍摄时间、位置和色彩等元数据。

该示例命令会对执行目录中由 `*.jpg` 匹配的全部 JPEG 进行原地有损压缩,并用 `--strip-all` 删除元数据;没有指定独立输出目录、预览或备份。如果代理在含原始照片的目录直接运行,可能降低全部匹配文件的质量并不可逆地移除 EXIF、版权或色彩相关信息。用户可要求只处理明确列出的副本并保留原件和必要元数据。

SKILL.md:273来自说明文档打开原文件
# Optimize JPEG (using jpegoptim)jpegoptim --max=80 --strip-all *.jpg
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。未发现风险

Skill 逻辑拆解

8 个说明模块

该 Skill 是营销图片工作指南:先读取项目中的产品营销背景文件,再根据用途、平台、尺寸、品牌资产和预算选择 AI、设计工具、截图或素材库方案。提供的材料中没有自动执行脚本。

查看原文
SKILL.md:15来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:38来自说明文档打开原文件
Pick the right tool for the job:

对于真实产品界面,该 Skill 明确反对用 AI 虚构截图,改为要求捕获真实产品截图、套入设备框架并添加标注。

查看原文
SKILL.md:188来自说明文档打开原文件
Showcase your product UI in context. AI models hallucinate UI — don't use them for this.1. **Capture real screenshots** of your product at 2x resolution2. **Frame in device mockups** — use browser frame, laptop, or phone templates3. **Add context** — callout arrows, feature labels, before/after comparisons4. **Annotate with code** — Hyperframes or HTML/CSS for programmatic overlays

图片生成可能使用 Google、Black Forest Labs、Ideogram、OpenAI 等外部服务,其中部分服务收费;该 Skill 会询问用户是否有相应 API 密钥及预算,但没有指示用户粘贴密钥值。

查看原文
SKILL.md:30来自说明文档打开原文件
### 3. Technical Context- Do you have API keys for any image tools? (Gemini, Replicate/Flux, Ideogram)- Budget constraints? (Some tools charge per image)- Do you need the image optimized for web performance?
SKILL.md:58来自说明文档打开原文件
|-------|----------|:-:|-----|------|| **Gemini Image** (Google, "Nano Banana" / Nano Banana Pro) | All-around, editing, multi-image reference, text rendering | Good | [Gemini API](https://ai.google.dev/gemini-api/docs/image-generation) | Check [pricing](https://ai.google.dev/gemini-api/docs/pricing) || **Flux** (Black Forest Labs — Pro 1.1, Kontext, Dev, Schnell) | Photorealism, brand consistency, batch; Kontext for in-image editing | Limited | [BFL API](https://docs.bfl.ai/), Replicate, fal.ai | Check [pricing](https://docs.bfl.ai/quick_start/pricing) || **Ideogram 3.0** | Typography, branded graphics, accurate text rendering | Best | [Ideogram API](https://developer.ideogram.ai/) | Check [pricing](https://about.ideogram.ai/api-pricing) || **ChatGPT Images 2.0 / GPT Image** (OpenAI) | General purpose, ChatGPT integration, native editing | Good | [OpenAI API](https://platform.openai.com/docs/guides/image-generation) | Check [pricing](https://platform.openai.com/docs/pricing) || **Midjourney v7** | Artistic, high-aesthetic, art-directed visuals | Improved | No official API; Discord + Web | Subscription-based || **Recraft V3** | Vector + brand-consistent illustrations, design assets | Strong | [Recraft API](https://www.recraft.ai/docs) | Per-credit || **Stable Diffusion 3.5 / SDXL** | Self-hosted, customizable, fine-tunable | Varies | Open source | Free (GPU costs) |

优化部分给出可复制的命令行示例,包括转换文件、批量处理当前目录图片、修改 JPEG,以及向指定网站发起请求并解析页面。它们是示例代码,不代表安装 Skill 时自动运行。

查看原文
SKILL.md:264来自说明文档打开原文件
### Quick Optimization Commands```bash# Convert to WebP (using cwebp)cwebp -q 80 input.png -o output.webp# Batch convert with ImageMagickmogrify -format webp -quality 80 *.png# Optimize JPEG (using jpegoptim)jpegoptim --max=80 --strip-all *.jpg# Check image sizes on a pagecurl -s https://yoursite.com | grep -oP 'src="[^"]+\.(jpg|png|webp)"' | head -20```
从这里开始 · 工作说明SKILL.md
image
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 2 个章节,可在原文件中查看。

文件引用关系图

1 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录3 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/ai-image-prompting.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/ai-image-prompting.md配套文件

代码和说明中提到的操作

连接外部网站
SKILL.md:58来自说明文档打开原文件
|-------|----------|:-:|-----|------|| **Gemini Image** (Google, "Nano Banana" / Nano Banana Pro) | All-around, editing, multi-image reference, text rendering | Good | [Gemini API](https://ai.google.dev/gemini-api/docs/image-generation) | Check [pricing](https://ai.google.dev/gemini-api/docs/pricing) || **Flux** (Black Forest Labs — Pro 1.1, Kontext, Dev, Schnell) | Photorealism, brand consistency, batch; Kontext for in-image editing | Limited | [BFL API](https://docs.bfl.ai/), Replicate, fal.ai | Check [pricing](https://docs.bfl.ai/quic 
SKILL.md:59来自说明文档打开原文件
| **Gemini Image** (Google, "Nano Banana" / Nano Banana Pro) | All-around, editing, multi-image reference, text rendering | Good | [Gemini API](https://ai.google.dev/gemini-api/docs/image-generation) | Check [pricing](https://ai.google.dev/ | **Flux** (Black Forest Labs — Pro 1.1, Kontext, Dev, Schnell) | Photorealism, brand consistency, batch; Kontext for in-image editing | Limited | [BFL API](https://docs.bfl.ai/), Replicate, fal.ai | Check [pricing](https://docs.bfl.ai/quick_start/pricing) || **Ideogram 3.0** | Typography, branded graphics, accurate text rendering | Best | [Ideogram API](https://developer.ideogram.ai/) | Check [pricing](https://about.ideogram.ai/api-pricing) |
SKILL.md:60来自说明文档打开原文件
| **Flux** (Black Forest Labs — Pro 1.1, Kontext, Dev, Schnell) | Photorealism, brand consistency, batch; Kontext for in-image editing | Limited | [BFL API](https://docs.bfl.ai/), Replicate, fal.ai | Check [pricing](https://docs.bfl.ai/quic | **Ideogram 3.0** | Typography, branded graphics, accurate text rendering | Best | [Ideogram API](https://developer.ideogram.ai/) | Check [pricing](https://about.ideogram.ai/api-pricing) || **ChatGPT Images 2.0 / GPT Image** (OpenAI) | General purpose, ChatGPT integration, native editing | Good | [OpenAI API](https://platform.openai.com/docs/guides/image-generation) | Check [pricing](https://platform.openai.com/docs/pricing) 
运行命令
SKILL.md:266来自说明文档打开原文件
```bash# Convert to WebP (using cwebp)
读取了多少行
661
文件校验值(用于核对版本)
3bb9c1a9e1d0b396e28732a5876162da12ccba1ece3d7cf3ea3fc17b2e752899